Duplication of an Organization: What CFEs Should Know About Business Identity Theft
Jan 01, 0001
Jan 01, 0001
For years we have been warned about the threat of identity theft and the need to protect our personal information from those who seek to misuse it; however, the same emphasis has not been placed on business identity theft.
January 2014
By Zach Capers, CFE
For years we have been warned about the threat of identity theft and the need to protect our personal information from those who seek to misuse it. However, the same emphasis has not been placed on business identity theft.
Business identity theft can be described as the misappropriation of an organization's tax identification number or other sensitive information necessary to imitate the identity of the business for illicit purposes. Criminals obtain tax identification numbers through various means, such as searching for them online, examining filings with securities regulators, reviewing tax forms, phishing or social engineering.
Fraudulent Changes to Official Records
Further complicating matters is the manipulation of company registration records on file with government entities — an insidious practice that often coincides with a business identity theft scheme. Fraudsters sometimes make changes to a company's official address, board members, salaries or other pertinent information to ease the implementation of a scheme. Thus, for example, when a business identity thief applies for a fraudulent line of credit in the name of a victim company, the application appears legitimate because the official records checked by creditors have been manipulated beforehand.
Various Schemes Perpetuated
Numerous schemes related to business identity theft have been reported, running the gamut from fraudulent credit card applications to complex multi-million dollar bogus stock sales. In some cases, long-dormant businesses have been fraudulently re-instated and used for nefarious purposes.
Tax-related fraud schemes can also result from the theft of business identities. Fraudsters sometimes submit bogus tax forms in an effort to receive a fraudulent federal tax refund. In 2013, a well-known seafood chain in the U.S. was victimized by a tax refund scheme wherein fraudsters submitted bogus tax forms for income totaling more than $4 million. The IRS tends to assume that submissions of this kind are legitimate, leaving the victimized company liable for invalid payroll taxes that can take significant time and effort to resolve.
Mimicked businesses are not the only victims of these schemes. Financial institutions are often stuck with a bad loan that will not be paid back. Retailers, such as office supply companies, must absorb losses due to merchandise sold to identity thieves on credit.
Small Business Owners Vulnerable
Owners of small businesses are particularly at risk for business identity theft. This segment of the business community possesses the lines of credit, capital and other features desired by fraudsters, while often lacking the resources and technology needed to properly defend against identity theft. Smaller companies and sole proprietorships often rely heavily on the owner's personal credit, making the impact of business identity theft even more destructive. Furthermore, small businesses might be especially wary of revealing identity theft out of fear that consumers will take their business to a larger company that ostensibly offers an increased level of data security.
Dearth of Data
Data regarding business identity theft is limited for several reasons. Businesses might be reticent to report identity theft due to the negative impact that it might have on their reputation. The surreptitious nature of most business identity theft schemes can also contribute to a lack of reporting. As businesses typically exist on a much greater scale than individuals, identity theft often takes much longer to be noticed, or goes overlooked entirely in some cases. While the disclosure of data breaches affecting consumers' personal data is required by law, there is generally no such requirement that breaches related to analogous business data be reported.
Combating Business Identity Theft
Several organizations are beginning to fight back. In the UK, the Protected Online Filing (PROOF) Service has been implemented to prevent unauthorized changes to business registration records. In the U.S., several states, including California, South Dakota, Georgia and Colorado, furnish detailed information regarding business identity theft, and businesses are given the option to receive an email anytime that a change is made to their official records. Additionally, the National Association of Secretaries of State (NASS) has developed a business identity theft task force with the intent to battle the growing problem.
Several practical measures can be taken to reduce your organization's exposure to business identity theft, including:
Ensure that your organization's tax identification number is protected in the same manner as personal identification numbers.
Regularly verify the accuracy of your organization's official registration records.
Check to see if the applicable registration office offers notifications when changes are made to your organization's record.
Only provide your company's sensitive identifying information when absolutely necessary.
Verify the security of any website through which your organization transmits sensitive data.
Shred sensitive company documents using a micro-cut shredder.
If you suspect your organization has already been victimized by business identity theft, take the following steps:
File a report with local law enforcement.
Contact the major business credit agencies, including Equifax, Experian, TransUnion and Dunn and Bradstreet, to report the fraudulent activity and obtain a credit report to check for additional fraudulent activity.
Contact all credit card companies, financial institutions and other creditors to alert them to the possibility of fraudulent activity.
Verify that all information on file with the applicable registration office (e.g., Companies House in the UK, secretary of state's office in the U.S.) is correct and has not been changed covertly.
The legal framework concerning identity theft has largely been formulated with individuals in mind, rather than businesses, leaving the prevention and prosecution of business-specific identify theft more difficult. Like personal identity theft before it, the most important step in addressing the problem is by increasing public awareness that it exists.